ISO 27001 Experts in Frankfurt
in minutes from over 15,000 CVs with the power of AIHire experts who build and run ISO/IEC 27001-ready information security management systems, map controls to real risks, prepare audits, and close gaps in policies and evidence. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Frankfurt, who have recently used ISO 27001
Dustin Dehez
Last position:
External consultant at Deutsche Leasing
2nd LoD/Change the Bank (CtB)
- CtB: External consultant and workstream lead for rectifying findings by BaFin following a special IT audit in the 2nd LoD, management of the work package for revising the ICT Risk Management & ICT Asset Classification in accordance with DORA Chapter 2, the processes for structural analysis, protection requirements, and control assessments (4 FTEs).
Robert Francia
Last position:
Interim Project Manager at IT services company of a regional energy supplier
- Delivery of various end-customer projects in server and network infrastructure on time, in quality, and within budget.
- Project 1: Firewall renewal, replacement of an ASA firewall with a Fortinet firewall at an automotive supplier.
- Project 2: Migration of file services from dedicated servers at 5 branch locations into a central managed file service, including DHCP, directory, and print services, as well as decommissioning of the old domain controllers.
- Project 3: Renewal of the network infrastructure at the headquarters and branch locations of a logistics company and transition of the LAN, WLAN, and firewall environments into a managed network service.
- Project 4: Network renewal, replacement of the core and access switches at the headquarters of a medical technology company and transition into a managed network service.
- Project 5: Firewall renewal, replacement of an ASA firewall with a Fortinet firewall for a city.
- Environment: ASA and Fortinet firewalls, Cisco network components, ITSM Heat/Ivanti, Confluence.
Prasad Tilloo
Last position:
Solution Architect / Senior Manager – DTC E-Commerce Platform at BRITA
- Led discovery phase and POC for Shopware to Shopify Plus migration across EMEA markets, evaluating platform suitability, technical architecture, and multi-brand/multi-country capabilities against business requirements.
- Designed reference architecture for Shopify Plus implementation incorporating headless front-end patterns (Vue.js, Nuxt.js), CMS integration (Magnolia), and Azure middleware (APIM, Functions, Logic Apps, Service Bus) for 11 EMEA markets.
- Defined migration strategy analyzing data mapping, cutover approach, and zero-downtime deployment patterns using Varnish caching, GitOps pipelines, and CI/CD orchestration across six vendor teams.
- Architected multi-tenant Shopify Plus governance model with centralized admin, localized storefront customization, and compliance controls (GDPR, data residency).
- Prototyped AI-driven search optimization (LLM.txt, JSON-LD) for product discoverability in Google AI results, demonstrating post-launch performance opportunities.
- Defined EMEA expansion roadmap for 15+ markets through C-level strategic workshops, identifying phased rollout, market-specific configurations, and resource requirements.
- Tech Stack: React, Nuxt.js, Vue.js, Magnolia CMS, Shopware, Shopify Plus, Azure (APIM, Functions, Logic Apps, Service Bus, Front Door), Varnish, SAP, MS Dynamics, Docker, Kubernetes, GitHub Actions, PostgreSQL, Kafka
Mario Pucko
Last position:
Senior IT Project Manager / Program Lead – Network Strategy 2030 at ALDB GmbH
- Holistic responsibility for modernizing and expanding federal networks and upgrading critical data center and telecom infrastructure in the high-security agency environment of BDBOS
- Planning and management of the expansion of national BOS network infrastructure in the VS-NfD/KRITIS environment with technical decision authority at the architecture and component level (Cisco, Layer 2/3, WAN redundancy)
- Planning, tendering (EVB-IT/UVgO) and oversight of the upgrade of security-critical telecom infrastructure for emergency call 110/112 (ACD)
- Capacity planning, rack integration, structured cabling, power supply, cooling concept (CRAC/In-Row) and DCIM monitoring for data center expansion
- Building the IT department from scratch: structures, governance, processes, team recruiting, vendor selection and long-term IT strategy
- Planning and managing infrastructure and application migrations: migration strategies, batch planning, hypercare stabilization and rollback concepts
- Creating vendor-neutral specifications (telecom systems, signature solutions) according to EVB-IT and UVgO; contract award and vendor management
- Setting up a secure IT environment according to BSI basic protection, ISO 27001 and VS-NfD; developing IT security concepts and CMDB analyses
- Hands-on program leadership: decision papers for management and steering committees, risk management, reporting and change request control
Noel Lang
Last position:
Founder & Lead Engineer at ausbildung-in-der-it.de
- Platform established and running stably; deliberately reducing my involvement to refocus on an engineering mandate in the financial sector.
- Built an own SaaS learning platform from the ground up and scaled it to over 20,000 users (over 6,000 courses sold, B2C and B2B); end-to-end ownership from development through infrastructure to operations.
- Built a lab environment that provisions an isolated Linux container per user (Docker, Traefik, Go), including automatic provisioning and a dedicated subdomain per user.
- Integrated LLM features into the product and accelerated development end-to-end with AI-assisted workflows (Claude Code, Codex); CI/CD with automated tests.
Achim Klein
Last position:
Portfolio Manager, Consultant, Leadership Coach at Abbvie Deutschland GmbH &Co. KG
- Management and optimization of a portfolio of about 100 projects (launches, in-field solutions, data & analytics, digital solutions, digital products)
- Optimization of the existing project standard (playbook) and alignment with the European and global organization (USA)
- Coaching project managers on setup, planning, cooperation with business, GDPR, GxP, data security and launches
- Preparing projects for works council information and project closeout communication
- Optimization of resource management (tracking, allocation, prioritization)
- Taking over individual project leads (off-/transboarding, event management, checking whether WhatsApp is allowed on a business smartphone)
- Supporting the hiring of external project managers
- Optimization of meeting structure, project controlling (KPIs), change and demand management
- Optimization of risk, issue, dependency and quality management and support during internal audits (GxP)
- Optimization of the portfolio steering tool (Smartsheet) on national, European and global level
- Design and implementation of a Business Value Complexity Scoring
- Building a strategic PMO with a sister department and optimizing cross-functional teams
- Reporting, communication and escalation at management level
- Leadership coaching for several future leaders (short-time assignment)
- Development of the concepts "PPM as a Service" and "Internal Customer Approach"
- Development and review of a concept "AI Data Governance" including roles and processes
- Selection and onboarding of the successor
Najat Diamante
Last position:
Freelance Consultant Microsoft Purview at Bechtlee IT-Systemhaus
- Design and global rollout of sensitivity labels (confidentiality labels) for automated classification and encryption of business-critical data.
- Definition and rollout of Data Loss Prevention (DLP) policies to protect IP and personal data across endpoints, Exchange, SharePoint, Teams, and non-Microsoft clouds.
- Setup of Insider Risk Management policies to detect and contain excessive data leaks and risky user behavior.
- Implementation of GDPR and retention requirements through automated retention policies and structured records management.
- Technical support for legal teams in internal and external investigations using eDiscovery (Standard/Premium) and Content Search.
- Continuous improvement of the security and compliance level by reviewing the Microsoft Compliance Manager and closing gaps (regulations such as ISO 27001, NIS-2)
GĂĽnther Eufinger
Last position:
Senior Consultant at ISMS Rollout – Information Security Certification (ISO 27001)
- Built and successfully certified the Information Security Management System (ISMS) according to ISO 27001 in seven country organizations (Ghana, India, Bangladesh, Uzbekistan, Serbia, Kosovo, Albania).
- Full implementation of the ISMS from kick-off phase to certification, including defining the governance structure and process landscape.
- Developed and delivered target-group-specific trainings, workshops, and coaching sessions for local responsible persons on the basics of information security and ISMS operations.
- Designed and continuously improved training concepts and content to increase understanding and acceptance.
- Identified and implemented improvements in processes and tools, including risk management for international projects.
- Optimized central ISMS core processes from the idea through pilot operation and fine-tuning to global rollout.
- Optimized knowledge management, as well as work aids and methods for the global ISMS team.
- Built and moderated cross-functional coordination with key interfaces to the ISMS.
- Microsoft Teams, Excel, SharePoint Lists, Power Apps.
Andreas Ilias
Last position:
Cybersecurity Specialist Assessor at Bundesnetzagentur
- Recognition of national notified bodies
- Preparation of cybersecurity competency reports
- EU Radio Equipment Directive
Marco Trautmann
Last position:
Chief Financial Officer & ExCo Member at Senacor Technologies AG
- Led assessment and preparation for finance and business management transformation including roll-out of SAP S/4 HANA Cloud, Public Edition.
- Enhanced financial and project reporting by streamlining tools and introducing a management dashboard.
- Introduced opportunity management reporting as part of business operations activities.
- Prepared annual financial statements (HGB).
- Directed annual budget development and aligned it with the ExCo.
Markus Marschollek
Last position:
Project Manager / Senior Consultant (multiple projects) at gkv informatik
- Project manager controlling the update to ISO 27001:2022 (certification from ISO 27002:2013 to ISO 27002:2022) including gap analysis, project planning, preparation of internal and external audits, and creation and maintenance of required documentation.
- Coordination of adjusting existing measures and implementing new measures according to the new standard’s requirements, as well as continuous monitoring and adjustment of these measures.
- Regular reporting to management on progress and risks.
- Senior consultant supporting audit reviews with a focus on critical infrastructures (KRITIS), including resolving findings, creating and updating evidence documents, and amending provider contracts.
- Senior consultant reviewing all deliverables and responsibilities of the IT provider according to the existing contract: identification of over 1500 deliverables & obligations (D&O), setup of a D&O tracker (claim register), and joint expert review with service owners for various service descriptions (e.g. IT service management, workplace and print services, application and desktop services, endpoint management, email including archiving, file services, software packaging, certification, distribution).
- Senior consultant adjusting service scopes in existing service descriptions to enable end-to-end service responsibility of the provider, including identification and analysis of use cases, process analysis and optimization (incident, problem, change), as well as recording and documenting all software products in LeanIX and documenting the contract change.
- Focused services: managed software service, application and desktop service, workplace and print services, web server service, container service, M365, SAP/Oscare, output management systems (OMS), telephony and omnichannel management service.
- Project manager steering a benchmark based on the existing IT contract, including coordination of the entire benchmark process between the benchmarker, IT provider and client, review of benchmark results, and preparation and conduct of price negotiations with the IT provider.
Fabrizio Di Carlo
Last position:
Managing Director at ContrailRisks Germany
- Founded and lead a cybersecurity advisory firm focused on virtual CISO services for financial, SaaS, and critical infrastructure clients.
- Advise executive teams on cyber risk, regulatory compliance (DORA, NIS2, ISO 27001), and incident preparedness.
- Built and executed security programs from scratch, driving measurable maturity improvements.
- Delivered tailored risk assessments, policies, and cloud security guidance (AWS, Azure).
- Scaled the business through client acquisition, partnerships (Vanta, AWS, etc), and a network of senior consultants.
Kurt Rosenberg
Last position:
Lead Solution Architect (AI HealthTech) / interim CTO & Product Co-Owner at Physio-Agil Frankfurt
- General CTO responsibilities (architectural design, operational setup, external runtime product evaluation, investor buy-in, regulatory compliance).
- Software development oversight (implementation on deep-dive-in) plus workflow design.
- Product co-ownership.
- Tech/tools/frameworks: proprietary software (Java, JavaScript), Kubernetes, Postgres, MiniIO, Ollama (internal), several xAI API (external), OpenTofu (Terraform), Keycloak, Kafka, Prometheus, ELK Stack, GitHub, GitHub Workflows, Argo CD, ISO 27001, BSI-ISM, EU AI Act.
Dmitrii Shatov
Last position:
IT Risk & Compliance | DORA | IT Regulatory & Operational Resilience Senior Consultant at Jefferies GmbH
Leading Jefferies’ DORA-driven operational resilience programme by strengthening ICT risk governance, control design, and regulatory readiness across key technology and outsourcing domains. Partnering with senior stakeholders to translate regulatory requirements into pragmatic governance, reporting, and assurance processes suitable for a global investment banking environment.
- Developed the Enterprise Register of Information (DORA Art. 28.3) to align with regulatory requirements.
- Defined and embedded ICT Risk Appetite and tolerance levels aligned to the Global Operational Risk Framework, strengthening decision-making and risk acceptance governance.
- Drove audit readiness by reviewing and re-drafting 50+ IT & Information Security policies, improving clarity, ownership, and control alignment.
- Oversaw the Operational Resilience Testing Programme (including penetration testing) and tracked remediation to closure, strengthening control assurance and reducing open findings.
- Aligned 10+ intra-group agreements with DORA regulatory standards.
- Enhanced executive-level decision-making with an enterprise ICT Risk Dashboard featuring KPIs/KRIs.
Tobias Greiner
Last position:
Head of IT D-A-CH (CIO) at Sodexo Service GmbH
- Responsible for IT strategy and operational IT governance in the D-A-CH region, covering infrastructure, applications, operations, security, and support
- Developed and implemented a strategic IT transformation to improve scalability, efficiency, and security of IT systems
- Managed a team of 25 specialists and coordinated with global and regional IT stakeholders
- Deployed a centralized IT service model for 250+ sites to standardize and optimize processes
- Supported and technically executed a carve-out to ensure business continuity
- Introduced modern cloud technologies and automation solutions to optimize processes
- Ensured compliance with ISO 27001, GDPR, and ITIL standards to minimize security risks
- Reduced IT costs by 20% through cloud migration and IT consolidation
- Built and led a high-performing IT team with focus on innovation and service orientation
- Led IT transformation projects including ERP migration, IT security, and digitalization
- Improved IT security level by implementing ISO 27001 and GDPR-compliant processes
- Optimized service times by 30% through AI-powered process automation
Discover over 15,000 top freelancers
Statistics of experts using ISO 27001
Aggregated from the professional profiles of matched freelancers.
Experience
20 years (Germany: 22 years)
Position duration
2.2 years (Germany: 2.6 years)
Positions per freelancer
13
Top business areas
Information Technology, Operations, Project Management
Top industries
Information Technology, Banking and Finance, Professional Services
Certification focus areas
Information Technology, Project Management, Quality Assurance
Bachelor's degree or higher
100% (Germany: 88%)
Master's degree or higher
56% (Germany: 54%)
Doctorate
6% (Germany: 10%)
Certifications per freelancer
6
Most common languages
English, German, French
Speak two or more languages
100% (Germany: 97%)
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Frankfurt are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Frankfurt using ISO 27001
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
ISO 27001 in practice
ISO 27001 is the standard for an information security management system, often called an ISMS. It helps companies define controls, manage risk, and prove that security is handled in a structured way. Teams use it to support customer trust, supplier reviews, and audit readiness.
Typical deliverables
- ISMS scope and risk assessment
- Statement of Applicability and control mapping
- Policies, procedures, and evidence packs
- Internal audit support and corrective actions
- Certification preparation and follow-up
Where specialists add value
Companies bring in freelance experts when they need to start an ISMS, prepare for certification, or repair gaps after a failed audit. In Frankfurt, this often matters for finance, logistics, SaaS, and any business handling sensitive client data or cross-border operations. The work is usually a mix of remote collaboration and focused on-site workshops.
What strong experts do
Good professionals do more than write documents. They translate ISO/IEC 27001 into controls people can actually follow, align security with legal and business needs, and keep records audit-ready. They also know how to work with ISO 27002 guidance, risk treatment plans, and internal stakeholders without creating unnecessary bureaucracy.
Related skills
- Risk assessment and control design
- Security policies and awareness training
- Supplier and third-party reviews
- Audit evidence collection and gap analysis
- Business continuity and incident response links
Choosing the right help
Use a specialist when you need practical implementation, not just a checklist. The best experts bring experience with ISMS design, certification support, and operational security, and they explain what must be documented versus what must truly change. That is what turns ISO 27001 from paperwork into a working system.
Frequently asked questions
Everything clients usually want to know about ISO 27001, in one place.
ISO 27001 is used to build and run an information security management system, usually called an ISMS. It helps a company define risks, apply controls, and show that security is managed in a consistent way. Many teams use it to support customer due diligence, supplier reviews, and certification work.
ISO/IEC 27001 is the full standard name, and ISO 27001 is the common short form. In practice, people use both names to mean the same information security management standard. When you search for help, using either term is fine.
ISO 27001 defines the management system and the requirements a company must meet. ISO 27002 is a guidance standard that explains security controls in more detail. A strong specialist knows how to use both together without treating them as the same thing.
A strong ISO 27001 freelancer usually also knows risk assessment, control design, policy writing, and audit preparation. Useful adjacent skills include business continuity, incident response, supplier management, and basic legal or compliance awareness. They should be able to explain security in plain language to different teams.
The right depth depends on the goal. A simple gap review needs less support than building an ISMS from scratch or preparing for certification in Frankfurt, where many companies expect clear evidence and tight coordination. The best expert is the one who has done the same type of work before.
ISO 27001 work can often be done remotely because much of it is documentation, interviews, and evidence review. On-site time helps for workshops, leadership alignment, and process mapping with operational teams. Many companies in Frankfurt prefer a hybrid setup for that reason.
Look for someone who can show how they turned security requirements into practical controls and audit evidence. A good ISO 27001 specialist asks about scope, risk, ownership, and current gaps before suggesting templates. If they only talk about certificates and not daily operations, that is a warning sign.
Companies usually hire ISO 27001 help when they are starting an ISMS, preparing for certification, responding to customer security reviews, or fixing audit findings. In Frankfurt, this often comes up in regulated sectors and data-heavy services. The best support is practical and focused on closing real gaps.
The average hourly rate of freelancers in Frankfurt, Germany who have used ISO 27001 in their recent projects is 118 €, which corresponds to a daily rate of about 942 € based on an 8-hour working day.
Of the freelancers in Frankfurt, Germany who have used ISO 27001 in their recent projects, 100% hold at least a Bachelor's degree, 56% hold at least a Master's degree, and 6% hold a doctorate.
On average, freelancers in Frankfurt, Germany who have used ISO 27001 in their recent projects have 20 years of professional experience, with a single engagement typically lasting around 2.2 years.
The most common languages among freelancers in Frankfurt, Germany who have used ISO 27001 in their recent projects are English (100%), German (95%), and French (23%).
The most common industries among freelancers in Frankfurt, Germany who have used ISO 27001 in their recent projects are Information Technology (86%), Banking and Finance (77%), and Professional Services (59%).
The most common business areas among freelancers in Frankfurt, Germany who have used ISO 27001 in their recent projects are Information Technology (100%), Operations (82%), and Project Management (82%).
Main locations of FRATCH Experts, who have recently used ISO 27001
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Hamburg
Munich
Cologne
Stuttgart
Dusseldorf
Dortmund
Essen